Crypto news

15.08.2026
19:05

Attack on Coldcard: vulnerability in key generation resulted in a loss of $112 million — incident analysis

hack

A large-scale campaign against Coldcard hardware wallet owners has resulted in a confirmed theft of at least 1,778.84 BTC, equivalent to $112.7 million. Monitoring shows that no new successful hacks have been recorded since August 6, but this is no reason for complacency—the full picture of the incident is far deeper than it seems at first glance.

The Root of the Problem: A Hidden Bug in Entropy

The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and then drained the funds. The cause lies in a firmware update from Coinkite in 2021. A change to the cryptographic entropy generation mechanism led to incorrect operation of the random number generator. The devices silently switched to an alternative entropy source, which proved critically weak for protecting private keys. The problem accumulated over years but only materialized now, when attackers gained sufficient computing power to reproduce the keys.

Who Is Behind the Attack and Where the Coins Went

This is not about a single hacker. Analysis has revealed at least 33 separate activity chains, indicating that several groups exploited the vulnerability simultaneously. Of the confirmed stolen funds, about 1,531 BTC remain on the attackers' addresses, while roughly 246 BTC have already been moved. A significant portion—about 65%—passed through CoinJoin transactions, complicating tracking. The remaining coins are moving via the Peel Chain scheme, where small transactions are repeatedly split off from large amounts. Some funds have been spotted on centralized exchanges and cross-chain bridges, and address lists have already been shared with law enforcement and compliance companies.

A Blow to the Self-Custody Ideology

The incident strikes not only at wallets but also at the very narrative of self-custody. The victims are users who approached security with maximum responsibility: no shady exchanges or risky DeFi protocols, only a hardware wallet. After the attacks began, a sharp influx of bitcoins to exchanges was observed: over 22,000 BTC flowed in during the first four days, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC. This is a classic fear reaction, but it only confirms that trust in single devices has been undermined.

Multisignature as a Salvation and the Role of AI

Notably, no confirmed theft has affected multisignature addresses. Services like Casa and Anchorwatch are already reporting a sharp increase in clients moving assets into multisig vaults. However, it is important to understand: the problem is not in custodial solutions but in the single point of failure—whether it be an exchange, a manufacturer, or the user themselves. Distributing risk across multiple keys and independent components is not just a trend but a necessity.

Separately, the possible use of AI by attackers is concerning. Analysis points to the use of open LLM models without strict restrictions, which expands the capabilities for finding vulnerabilities. The paradox is that researchers from Bitcoin Red Team, on the contrary, face restrictions from American AI companies when trying to protect the ecosystem. This creates an asymmetry: attackers gain access to powerful tools faster than defenders.

My verdict: this incident is not just another hack but a systemic challenge to the industry. It demonstrates that even the most seemingly reliable solutions can contain hidden defects that manifest years later. In the first half of 2026, crypto projects already lost about $1.1 billion due to exploits, and this case only confirms: security is not a static product but a continuous process of auditing and adaptation. I recommend that anyone still using single-signature Coldcard devices migrate to multisig schemes immediately, without waiting for new surprises.